Courseiva
Perform threat hunting →mediumMultiple Select

SC-200 Perform threat hunting Practice Question

Which THREE of the following are key components of a successful threat hunting program in a Microsoft Defender XDR environment?

⚠ Common exam trap

SC-200 often tests the distinction between proactive threat hunting (hypothesis, MITRE ATT&CK, baselining) and reactive incident response (playbooks, alert triage), tempting candidates to select automation options.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Deep understanding of normal network behavior

A successful threat hunting program in Microsoft Defender XDR requires a deep understanding of normal network behavior (A), because establishing a baseline of legitimate activity lets hunters spot anomalies across endpoint, identity, email, and cloud telemetry that automated detections may miss. A clear hypothesis based on threat intelligence (B) is essential, since threat hunting is hypothesis-driven rather than alert-driven; hunters use intel to form testable assumptions about adversary behavior and then query Defender XDR advanced hunting (KQL) to validate or refute them. The use of the MITRE ATT&CK framework (C) is also a key component, as it maps observed techniques and tactics to a common taxonomy, helping hunters prioritize coverage gaps and structure hunts around known adversary TTPs. Automated incident response playbooks (D) belong to SOAR/automated investigation and response, not threat hunting, and reactive response to alerts (E) is the opposite of proactive hunting, so neither is a core component of a threat hunting program.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Deep understanding of normal network behavior

    Why this is correct

    Baselining normal network behaviour lets hunters spot anomalies such as beaconing, unusual lateral movement or data staging in Defender XDR telemetry. Without knowing what routine traffic looks like, distinguishing genuine malicious activity from benign administrative patterns is impossible, so this underpins every hypothesis.

  • ✓

    A clear hypothesis based on threat intelligence

    Why this is correct

    A hypothesis directs hunting rather than aimless querying. Deriving it from threat intelligence about actors targeting your sector focuses advanced hunting queries in Microsoft Defender XDR on specific TTPs, making detection of otherwise invisible activity far more likely within limited analyst time.

  • ✓

    Use of MITRE ATT&CK framework

    Why this is correct

    MITRE ATT&CK maps adversary tactics and techniques to concrete hunting queries, ensuring coverage gaps are identified rather than assumed. It gives Microsoft Defender XDR hunters a shared vocabulary and structured progression through the kill chain, preventing over-focus on a single technique.

  • ✗

    Automated incident response playbooks

    Why it's wrong here

    Automated incident response playbooks execute containment after detections fire; threat hunting is a hypothesis-driven, proactive search for undetected activity, so playbooks sit outside its components. They are tempting because automation is central to broader Defender XDR operations, where they are the right choice for response orchestration.

  • ✗

    Reactive response to alerts

    Why it's wrong here

    Reacting to alerts is detection-and-response, not hunting, which proactively searches for threats that generated no alert. It is tempting because alert triage is essential security operations work, and reactive handling is the correct approach for a question about incident response processes.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.